Conceptual

PHY-Layer Signature Scheme Securing Wi-Fi 6 Connection Establishment Against Relay and Spoofing

A backward-compatible defense for the unprotected connection-establishment phase of IEEE 802.11ax (Wi-Fi 6). A legitimate AP signs its MAC address and a timestamp, slices the signature, and embeds one slice into each unicast pre-authentication frame's PHY-layer preamble without extending frame size, chaining the frames with timing constraints that block relay and replay of authentic preambles. Stations verify APs from consistent PHY-header patterns without inspecting MAC headers, supporting concurrent multi-station verification, and the scheme is validated on a USRP testbed with 96-100% relay-attack detection plus formal security analysis.